<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:13:02 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:8617 — Moderate: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:8617</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: bpftool, AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core and 52 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* hw: cpu: intel: Native Branch History Injection (BHI) (CVE-2024-2201)
  * kernel: tcp: add sanity checks to rx zerocopy (CVE-2024-26640)
  * kernel: mptcp: fix data re-injection from stale subflow (CVE-2024-26826)
  * kernel: af_unix: Fix garbage collector racing against connect() (CVE-2024-26923)
  * kernel: mac802154: fix llsec key resources release in mac802154_llsec_key_del (CVE-2024-26961)
  * kernel: scsi: core: Fix unremoved procfs host directory regression (CVE-2024-26935)
  * kernel: tty: Fix out-of-bound vmalloc access in imageblit (CVE-2021-47383)
  * kernel: net/sched: taprio: extend minimum interval restriction to entire cycle too (CVE-2024-36244)
  * kernel: xfs: fix log recovery buffer allocation for the legacy h_size fixup (CVE-2024-39472)
  * kernel: netfilter: nft_inner: validate mandatory meta and payload (CVE-2024-39504)
  * kernel: USB: class: cdc-wdm: Fix CPU lockup caused by excessive log messages (CVE-2024-40904)
  * kernel: mptcp: ensure snd_una is properly initialized on connect (CVE-2024-40931)
  * kernel: ipv6: prevent possible NULL dereference in rt6_probe() (CVE-2024-40960)
  * kernel: ext4: do not create EA inode under buffer lock (CVE-2024-40972)
  * kernel: wifi: mt76: mt7921s: fix potential hung tasks during chip recovery (CVE-2024-40977)
  * kernel: net/sched: act_api: fix possible infinite loop in tcf_idr_check_alloc() (CVE-202…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: bpftool, AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core and 52 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* hw: cpu: intel: Native Branch History Injection (BHI) (CVE-2024-2201)
  * kernel: tcp: add sanity checks to rx zerocopy (CVE-2024-26640)
  * kernel: mptcp: fix data re-injection from stale subflow (CVE-2024-26826)
  * kernel: af_unix: Fix garbage collector racing against connect() (CVE-2024-26923)
  * kernel: mac802154: fix llsec key resources release in mac802154_llsec_key_del (CVE-2024-26961)
  * kernel: scsi: core: Fix unremoved procfs host directory regression (CVE-2024-26935)
  * kernel: tty: Fix out-of-bound vmalloc access in imageblit (CVE-2021-47383)
  * kernel: net/sched: taprio: extend minimum interval restriction to entire cycle too (CVE-2024-36244)
  * kernel: xfs: fix log recovery buffer allocation for the legacy h_size fixup (CVE-2024-39472)
  * kernel: netfilter: nft_inner: validate mandatory meta and payload (CVE-2024-39504)
  * kernel: USB: class: cdc-wdm: Fix CPU lockup caused by excessive log messages (CVE-2024-40904)
  * kernel: mptcp: ensure snd_una is properly initialized on connect (CVE-2024-40931)
  * kernel: ipv6: prevent possible NULL dereference in rt6_probe() (CVE-2024-40960)
  * kernel: ext4: do not create EA inode under buffer lock (CVE-2024-40972)
  * kernel: wifi: mt76: mt7921s: fix potential hung tasks during chip recovery (CVE-2024-40977)
  * kernel: net/sched: act_api: fix possible infinite loop in tcf_idr_check_alloc() (CVE-202…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:8617</guid>
    </item>
    <item>
      <title>bdu:2025-08075</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-08075</link>
      <description>bdu:2025-08075</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-08075</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-36244</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-36244</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-36244</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0778 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0778</link>
      <description>certfr-2024-avi-0778</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0778</guid>
    </item>
    <item>
      <title>EUVD-2026-320610</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-320610</link>
      <description>EUVD-2026-320610</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-320610</guid>
    </item>
    <item>
      <title>fkie_cve-2024-36244</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-36244</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/sched: taprio: extend minimum interval restriction to entire cycle too&lt;/p&gt;
&lt;p&gt;It is possible for syzbot to side-step the restriction imposed by the
blamed commit in the Fixes: tag, because the taprio UAPI permits a
cycle-time different from (and potentially shorter than) the sum of
entry intervals.&lt;/p&gt;
&lt;p&gt;We need one more restriction, which is that the cycle time itself must
be larger than N * ETH_ZLEN bit times, where N is the number of schedule
entries. This restriction needs to apply regardless of whether the cycle
time came from the user or was the implicit, auto-calculated value, so
we move the existing &amp;#34;cycle == 0&amp;#34; check outside the &amp;#34;if &amp;#34;(!new-&amp;gt;cycle_time)&amp;#34;
branch. This way covers both conditions and scenarios.&lt;/p&gt;
&lt;p&gt;Add a selftest which illustrates the issue triggered by syzbot.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/sched: taprio: extend minimum interval restriction to entire cycle too&lt;/p&gt;
&lt;p&gt;It is possible for syzbot to side-step the restriction imposed by the
blamed commit in the Fixes: tag, because the taprio UAPI permits a
cycle-time different from (and potentially shorter than) the sum of
entry intervals.&lt;/p&gt;
&lt;p&gt;We need one more restriction, which is that the cycle time itself must
be larger than N * ETH_ZLEN bit times, where N is the number of schedule
entries. This restriction needs to apply regardless of whether the cycle
time came from the user or was the implicit, auto-calculated value, so
we move the existing &amp;#34;cycle == 0&amp;#34; check outside the &amp;#34;if &amp;#34;(!new-&amp;gt;cycle_time)&amp;#34;
branch. This way covers both conditions and scenarios.&lt;/p&gt;
&lt;p&gt;Add a selftest which illustrates the issue triggered by syzbot.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-36244</guid>
    </item>
    <item>
      <title>GHSA-35qp-2m3w-q656</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-35qp-2m3w-q656</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/sched: taprio: extend minimum interval restriction to entire cycle too&lt;/p&gt;
&lt;p&gt;It is possible for syzbot to side-step the restriction imposed by the
blamed commit in the Fixes: tag, because the taprio UAPI permits a
cycle-time different from (and potentially shorter than) the sum of
entry intervals.&lt;/p&gt;
&lt;p&gt;We need one more restriction, which is that the cycle time itself must
be larger than N * ETH_ZLEN bit times, where N is the number of schedule
entries. This restriction needs to apply regardless of whether the cycle
time came from the user or was the implicit, auto-calculated value, so
we move the existing &amp;#34;cycle == 0&amp;#34; check outside the &amp;#34;if &amp;#34;(!new-&amp;gt;cycle_time)&amp;#34;
branch. This way covers both conditions and scenarios.&lt;/p&gt;
&lt;p&gt;Add a selftest which illustrates the issue triggered by syzbot.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/sched: taprio: extend minimum interval restriction to entire cycle too&lt;/p&gt;
&lt;p&gt;It is possible for syzbot to side-step the restriction imposed by the
blamed commit in the Fixes: tag, because the taprio UAPI permits a
cycle-time different from (and potentially shorter than) the sum of
entry intervals.&lt;/p&gt;
&lt;p&gt;We need one more restriction, which is that the cycle time itself must
be larger than N * ETH_ZLEN bit times, where N is the number of schedule
entries. This restriction needs to apply regardless of whether the cycle
time came from the user or was the implicit, auto-calculated value, so
we move the existing &amp;#34;cycle == 0&amp;#34; check outside the &amp;#34;if &amp;#34;(!new-&amp;gt;cycle_time)&amp;#34;
branch. This way covers both conditions and scenarios.&lt;/p&gt;
&lt;p&gt;Add a selftest which illustrates the issue triggered by syzbot.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-35qp-2m3w-q656</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-36244 — net/sched: taprio: extend minimum interval restriction to entire cycle too</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-36244</link>
      <description>msrc_CVE-2024-36244</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-36244</guid>
    </item>
    <item>
      <title>OESA-2024-2292 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2292</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
octeontx2-af: Use separate handlers for interrupts&#13;
&#13;
For PF to AF interrupt vector and VF to AF vector same
interrupt handler is registered which is causing race condition.
When two interrupts are raised to two CPUs at same time
then two cores serve same event corrupting the data.(CVE-2024-27030)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
media: go7007: fix a memleak in go7007_load_encoder&#13;
&#13;
In go7007_load_encoder, bounce(i.e. go-&amp;amp;gt;boot_fw), is allocated without
a deallocation thereafter. After the following call chain:&#13;
&#13;
saa7134_go7007_init
  |-&amp;amp;gt; go7007_boot_encoder
        |-&amp;amp;gt; go7007_load_encoder
  |-&amp;amp;gt; kfree(go)&#13;
&#13;
go is freed and thus bounce is leaked.(CVE-2024-27074)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
netfilter: nf_tables: use timestamp to check for set element timeout&#13;
&#13;
Add a timestamp field at the beginning of the transaction, store it
in the nftables per-netns area.&#13;
&#13;
Update set backend .insert, .deactivate and sync gc path to use the
timestamp, this avoids that an element expires while control plane
transaction is still unfinished.&#13;
&#13;
.lookup and .update, which are used from packet path, still use the
current time to check if the element has expired. And .get path and dump
also since this runs lockless under rcu read size lock. Then, ther…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
octeontx2-af: Use separate handlers for interrupts&#13;
&#13;
For PF to AF interrupt vector and VF to AF vector same
interrupt handler is registered which is causing race condition.
When two interrupts are raised to two CPUs at same time
then two cores serve same event corrupting the data.(CVE-2024-27030)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
media: go7007: fix a memleak in go7007_load_encoder&#13;
&#13;
In go7007_load_encoder, bounce(i.e. go-&amp;amp;gt;boot_fw), is allocated without
a deallocation thereafter. After the following call chain:&#13;
&#13;
saa7134_go7007_init
  |-&amp;amp;gt; go7007_boot_encoder
        |-&amp;amp;gt; go7007_load_encoder
  |-&amp;amp;gt; kfree(go)&#13;
&#13;
go is freed and thus bounce is leaked.(CVE-2024-27074)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
netfilter: nf_tables: use timestamp to check for set element timeout&#13;
&#13;
Add a timestamp field at the beginning of the transaction, store it
in the nftables per-netns area.&#13;
&#13;
Update set backend .insert, .deactivate and sync gc path to use the
timestamp, this avoids that an element expires while control plane
transaction is still unfinished.&#13;
&#13;
.lookup and .update, which are used from packet path, still use the
current time to check if the element has expired. And .get path and dump
also since this runs lockless under rcu read size lock. Then, ther…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2292</guid>
    </item>
    <item>
      <title>RHSA-2024:8157 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:8157</link>
      <description>&lt;p&gt;kernel: hwmon: (w83792d) Fix NULL pointer dereference by removing unnecessary structure field kernel: Local information disclosure on Intel(R) Atom(R) processors kernel: skbuff: skb_segment, Call zero copy functions before using skbuff frags kernel: net/sched: taprio: Limit TCA_TAPRIO_ATTR_SCHED_CYCLE_TIME to INT_MAX kernel: net/sched: taprio: extend minimum interval restriction to entire cycle too kernel: xfs: fix log recovery buffer allocation for the legacy h_size fixup kernel: firmware: cs_dsp: Use strnlen() on name fields in V1 wmfw files kernel: ibmvnic: Add tx check to prevent skb leak kernel: pinctrl: fix deadlock in create_pinctrl() when handling -EPROBE_DEFER kernel: sched: act_ct: take care of padding in struct zones_ht_key kernel: tipc: Return non-zero value from tipc_udp_addr2str() on error&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: hwmon: (w83792d) Fix NULL pointer dereference by removing unnecessary structure field kernel: Local information disclosure on Intel(R) Atom(R) processors kernel: skbuff: skb_segment, Call zero copy functions before using skbuff frags kernel: net/sched: taprio: Limit TCA_TAPRIO_ATTR_SCHED_CYCLE_TIME to INT_MAX kernel: net/sched: taprio: extend minimum interval restriction to entire cycle too kernel: xfs: fix log recovery buffer allocation for the legacy h_size fixup kernel: firmware: cs_dsp: Use strnlen() on name fields in V1 wmfw files kernel: ibmvnic: Add tx check to prevent skb leak kernel: pinctrl: fix deadlock in create_pinctrl() when handling -EPROBE_DEFER kernel: sched: act_ct: take care of padding in struct zones_ht_key kernel: tipc: Return non-zero value from tipc_udp_addr2str() on error&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:8157</guid>
    </item>
    <item>
      <title>RHSA-2024:8617 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:8617</link>
      <description>&lt;p&gt;kernel: tty: Fix out-of-bound vmalloc access in imageblit kernel: ext4: turn quotas off if mount failed after enabling quotas hw: cpu: intel: Native Branch History Injection (BHI) kernel: tcp: add sanity checks to rx zerocopy kernel: mptcp: fix data re-injection from stale subflow kernel: af_unix: Fix garbage collector racing against connect() kernel: scsi: core: Fix unremoved procfs host directory regression kernel: mac802154: fix llsec key resources release in mac802154_llsec_key_del kernel: net/sched: taprio: extend minimum interval restriction to entire cycle too kernel: xfs: fix log recovery buffer allocation for the legacy h_size fixup kernel: netfilter: nft_inner: validate mandatory meta and payload kernel: USB: class: cdc-wdm: Fix CPU lockup caused by excessive log messages kernel: mptcp: ensure snd_una is properly initialized on connect kernel: ipv6: prevent possible NULL dereference in rt6_probe() kernel: ext4: do not create EA inode under buffer lock kernel: wifi: mt76: mt7921s: fix potential hung tasks during chip recovery kernel: net/sched: act_api: fix possible infinite loop in tcf_idr_check_alloc() kernel: ext4: fix uninitialized ratelimit_state-&amp;amp;gt;lock access in __ext4_fill_super() kernel: netpoll: Fix race condition in netpoll_owner_active kernel: xfs: don&amp;amp;#39;t walk off the end of a directory data block kernel: xfs: add bounds checking to xlog_recover_process_data kernel: block: initialize integrity buffer to zero before writing it to media kernel: netfilt…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: tty: Fix out-of-bound vmalloc access in imageblit kernel: ext4: turn quotas off if mount failed after enabling quotas hw: cpu: intel: Native Branch History Injection (BHI) kernel: tcp: add sanity checks to rx zerocopy kernel: mptcp: fix data re-injection from stale subflow kernel: af_unix: Fix garbage collector racing against connect() kernel: scsi: core: Fix unremoved procfs host directory regression kernel: mac802154: fix llsec key resources release in mac802154_llsec_key_del kernel: net/sched: taprio: extend minimum interval restriction to entire cycle too kernel: xfs: fix log recovery buffer allocation for the legacy h_size fixup kernel: netfilter: nft_inner: validate mandatory meta and payload kernel: USB: class: cdc-wdm: Fix CPU lockup caused by excessive log messages kernel: mptcp: ensure snd_una is properly initialized on connect kernel: ipv6: prevent possible NULL dereference in rt6_probe() kernel: ext4: do not create EA inode under buffer lock kernel: wifi: mt76: mt7921s: fix potential hung tasks during chip recovery kernel: net/sched: act_api: fix possible infinite loop in tcf_idr_check_alloc() kernel: ext4: fix uninitialized ratelimit_state-&amp;amp;gt;lock access in __ext4_fill_super() kernel: netpoll: Fix race condition in netpoll_owner_active kernel: xfs: don&amp;amp;#39;t walk off the end of a directory data block kernel: xfs: add bounds checking to xlog_recover_process_data kernel: block: initialize integrity buffer to zero before writing it to media kernel: netfilt…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:8617</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:3983-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:3983-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:3983-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-36244</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-36244</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 155 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net/sched: taprio: extend minimum interval restriction to entire cycle too It is possible for syzbot to side-step the restriction imposed by the blamed commit in the Fixes: tag, because the taprio UAPI permits a cycle-time different from (and potentially shorter than) the sum of entry intervals. We need one more restriction, which is that the cycle time itself must be larger than N * ETH_ZLEN bit times, where N is the number of schedule entries. This restriction needs to apply regardless of whether the cycle time came from the user or was the implicit, auto-calculated value, so we move the existing &amp;#34;cycle == 0&amp;#34; check outside the &amp;#34;if &amp;#34;(!new-&amp;gt;cycle_time)&amp;#34; branch. This way covers both conditions and scenarios. Add a selftest which illustrates the issue triggered by syzbot.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 155 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net/sched: taprio: extend minimum interval restriction to entire cycle too It is possible for syzbot to side-step the restriction imposed by the blamed commit in the Fixes: tag, because the taprio UAPI permits a cycle-time different from (and potentially shorter than) the sum of entry intervals. We need one more restriction, which is that the cycle time itself must be larger than N * ETH_ZLEN bit times, where N is the number of schedule entries. This restriction needs to apply regardless of whether the cycle time came from the user or was the implicit, auto-calculated value, so we move the existing &amp;#34;cycle == 0&amp;#34; check outside the &amp;#34;if &amp;#34;(!new-&amp;gt;cycle_time)&amp;#34; branch. This way covers both conditions and scenarios. Add a selftest which illustrates the issue triggered by syzbot.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-36244</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1422 — Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1422</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1422</guid>
    </item>
  </channel>
</rss>
